Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

10 detectors match the current filters. tactic: TA0006 ✕ technique: T1557 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Machine Account NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that machine account NTLM authentication data has been relayed. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access, Lateral Movement
Analytics BIOC Multiple uncommon SSH Servers with the same Server host key Multiple uncommon SSH servers were observed using the same host key. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access
Analytics NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that NTLM authentication data has been relayed. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access, Lateral Movement
Analytics BIOC Possible authentication coercion An unusual Remote Procedure Call (RPC) was made to potentially cause authentication coercion. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Possible Distributed File System Namespace Management (DFSNM) abuse A possible abuse of Distributed File System Namespace Management (DFSNM). High Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Possible new DHCP server A DHCP response was sent from an unknown DHCP server. Attackers may send a DHCP response to a host in his LAN to inject a DNS server, route or WPAD server. Medium Platform Analytics XDR Agent Credential Access
Analytics Potential NTLM Relay Attack Multiple NTLM authentications were made to the same workstation and user from different IPs. This might indicate a potential NTLM Relay attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server Multiple NTLM authentications were made to the same Microsoft Configuration Manager site server and user from different IPs in a short period of time. This might indicate a potential NTLM Relay attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Uncommon WPAD queries There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access
Analytics BIOC Unusual Encrypting File System Remote call (EFSRPC) to domain controller An unusual Encrypting File System Remote call (EFSRPC) was made to a domain controller. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access